:OTL
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?affID=121562&babsrc=HP_ss&mntrId=529250E5493898DC
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?affID=121562&babsrc=HP_ss&mntrId=529250E5493898DC
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}&affID=121562&babsrc=SP_ss&mntrId=529250E5493898DC
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\..\SearchScopes\{5848C9F3-BA43-466e-ACB1-11B9D749AEF0}: "URL" = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
IE - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\..\SearchScopes\{729BA7C9-B347-49DE-9705-923CC5359E7C}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=819ED001-93B2-4022-9A3B-AE4258461E95&apn_sauid=203ACC13-A8CF-40CD-BD0D-B589FE0B1853
FF - prefs.js..browser.search.selectedEngine: "Delta Search"
[2013-04-19 14:21:03 | 000,000,000 | ---D | M] (Browwse2siAvee) -- C:\Users\Małgorzata Morawska\AppData\Roaming\mozilla\Firefox\Profiles\86o4c4f0.default\extensions\
[email protected][2013-04-19 14:24:56 | 000,000,000 | ---D | M] (Browwse2siAvee) -- C:\Users\Małgorzata Morawska\AppData\Roaming\mozilla\Firefox\Profiles\86o4c4f0.default\extensions\
[email protected][2013-05-06 06:57:17 | 000,006,487 | ---- | M] () -- C:\Users\Małgorzata Morawska\AppData\Roaming\mozilla\firefox\profiles\86o4c4f0.default\searchplugins\babylon.xml
[2013-05-06 06:57:17 | 000,006,487 | ---- | M] () -- C:\Users\Małgorzata Morawska\AppData\Roaming\mozilla\firefox\profiles\86o4c4f0.default\searchplugins\BrowserProtect.xml
[2013-02-27 15:03:17 | 000,001,294 | ---- | M] () -- C:\Users\Małgorzata Morawska\AppData\Roaming\mozilla\firefox\profiles\86o4c4f0.default\searchplugins\delta.xml
[2013-02-27 15:02:58 | 000,006,484 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O3 - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O4 - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000..\RunOnce: [Uninstall C:\Users\Małgorzata Morawska\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Małgorzata Morawska\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1" File not found
O4 - HKU\S-1-5-21-2720900084-3959965312-2166452236-1000..\RunOnce: [Uninstall C:\Users\Małgorzata Morawska\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Małgorzata Morawska\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64" File not found
O4 - HKU\S-1-5-21-2720900084-3959965312-2166452236-1002..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:
64bit: - Extra context menu item: Ściągaj z Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O8 - Extra context menu item: Ściągaj z Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261125~1.80\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
[2013-05-07 08:50:41 | 000,000,444 | -H-- | M] () -- C:\Windows\tasks\schedule!3036567561.job
:Files
C:\ProgramData\BrowserProtect
C:\Users\Małgorzata Morawska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
:Commands
[clearallrestorepoints]
[emptytemp]